Cross-Chain Bridge Exploit Hits Symbiosis, Highlighting Ongoing DeFi Bridge Risks
Symbiosis, a cross-chain DeFi protocol, shut down its native Bitcoin bridge on Friday after discovering an attacker had exploited its BridgeV2 contract to mint a massive amount of unbacked synthetic BTC (syBTC). The attack was detected around 04:28 UTC on September 11, prompting the team to immediately halt BTC routing, though other routing functions continued operating.
While the exploit generated over 2^62 units of synthetic BTC on BNB Chain and Ethereum, the attacker was only able to convert a small fraction of this into real value, roughly 4.39 WBTC on Ethereum, worth about $336,000. Investigators note that Bitcoin itself was never compromised; the vulnerability lay in how BridgeV2 authenticated cross-chain messages between its Portal and Synthesis contracts and its off-chain relayer network, which uses multi-party computation (MPC) signatures to validate transactions.
This incident follows closely behind a much larger $320 million breach on the Liquid Network days earlier, reinforcing concerns that cross-chain bridge infrastructure remains a persistent weak point in the DeFi ecosystem, even when the underlying blockchains they connect are secure.